Courseiva
mediumMultiple Choice

PT0-002 Practice Question: A penetration tester is using theHarvester tool…

A penetration tester is using theHarvester tool to gather email addresses and subdomains for a target domain. Which source is theHarvester commonly configured to use for passive reconnaissance?

⚠ Common exam trap

CompTIA often tests the distinction between passive and active reconnaissance, and the trap here is that candidates confuse Shodan (a passive search engine for devices) with theHarvester's passive email/subdomain gathering, or assume DNS zone transfer is passive when it is an active query that requires direct server interaction.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Google search

TheHarvester is a passive reconnaissance tool that collects emails, subdomains, and other data from public sources without directly interacting with the target. Google search is a primary source because theHarvester uses Google's search engine via its API or scraping to find indexed pages containing email addresses and subdomains, leveraging Google's dorking capabilities for passive data gathering.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Shodan

    Why it's wrong here

    Shodan is a search engine for internet-exposed devices, but theHarvester does not query it because Shodan requires an API key and returns IP/service data, not email addresses or domain-related subdomains that theHarvester targets. Moreover, Shodan's data is not indexed for email harvesting; its focus on banners and open ports makes it orthogonal to theHarvester's passive email and subdomain enumeration.

  • ✓

    Google search

    Why this is correct

    Google search is a primary source for theHarvester, as it uses search engine queries to passively scrape email addresses and subdomains from indexed pages without interacting directly with target infrastructure. The tool constructs Google dork-like queries (e.g., site:domain.com) and parses results, making it a purely passive OSINT technique for initial reconnaissance.

  • ✗

    DNS zone transfer

    Why it's wrong here

    DNS zone transfer is an active reconnaissance technique, because the tester directly queries a DNS server (AXFR request) and, if misconfigured, receives the entire zone file. This is fundamentally different from theHarvester's passive approach, which never sends packets to the target's authoritative servers; it relies on third-party sources like search engines and certificate logs.

  • ✗

    Social media APIs

    Why it's wrong here

    theHarvester does not leverage social media APIs because its passive collection model relies on search engine scraping and public certificate transparency logs; querying social APIs would require authentication tokens and violate the tool's lightweight, no-key approach. While social platforms may expose emails in public profiles, theHarvester's architecture predates and does not integrate those endpoints, so attempting to use them would necessitate custom scripting rather than theharvester itself.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.